{"api_version":"1","generated_at":"2026-07-23T09:20:35+00:00","cve":"CVE-2019-11641","urls":{"html":"https://cve.report/CVE-2019-11641","api":"https://cve.report/api/cve/CVE-2019-11641.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-11641","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-11641"},"summary":{"title":"CVE-2019-11641","description":"Anomali Agave (formerly Drupot) through 1.0.0 fails to avoid fingerprinting by including predictable data and minimal variation in size within HTML templates, giving attackers the ability to detect and avoid this system.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-05-01 18:29:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["CWE-330"],"metrics":[],"references":[{"url":"https://github.com/threatstream/agave/issues/1","name":"https://github.com/threatstream/agave/issues/1","refsource":"MISC","tags":["Issue Tracking","Third Party Advisory"],"title":"Fingerprinting · Issue #1 · pwnlandia/agave · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-11641","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-11641","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"11641","vulnerable":"1","versionEndIncluding":"1.0.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"anomali","cpe5":"agave","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-11641","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Anomali Agave (formerly Drupot) through 1.0.0 fails to avoid fingerprinting by including predictable data and minimal variation in size within HTML templates, giving attackers the ability to detect and avoid this system."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/threatstream/agave/issues/1","refsource":"MISC","name":"https://github.com/threatstream/agave/issues/1"}]}},"nvd":{"publishedDate":"2019-05-01 18:29:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["CWE-330"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:anomali:agave:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"11641","Ordinal":"149955","Title":"CVE-2019-11641","CVE":"CVE-2019-11641","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"11641","Ordinal":"1","NoteData":"Anomali Agave (formerly Drupot) through 1.0.0 fails to avoid fingerprinting by including predictable data and minimal variation in size within HTML templates, giving attackers the ability to detect and avoid this system.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"11641","Ordinal":"2","NoteData":"2019-05-01","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"11641","Ordinal":"3","NoteData":"2019-05-01","Type":"Other","Title":"Modified"}]}}}